Hatchet cross-tenant data exposure via missing authorization (CVE-2026-42572)
A missing authorization directive on Hatchet's GET /api/v1/stable/dags/tasks endpoint skipped the tenant-membership check, letting any authenticated user on the instance retrieve task metadata for DAGs belonging to other tenants. The issue is fixed in version 0.83.39.
Disclosed 14 May 2026 · Record updated 13 September 2026
Impact
Users authenticated to any tenant could query another tenant's DAG UUID and receive that tenant's task metadata, enabling cross-tenant information disclosure.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-42572
